Назад
Company hidden
19 часов назад

Senior Penetration Tester (iGaming)

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Serbia/Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Penetration Tester (iGaming): Strengthening high-load iGaming products through offensive security assessments across applications, infrastructure, cloud environments, mobile platforms, and payment flows with an accent on AWS, Kubernetes, APIs, and business-critical workflows. Focus on red-team and assumed-breach exercises, identifying complex vulnerabilities, and translating findings into practical remediation with engineering, product, fraud, and compliance stakeholders.

Location: Remote from Poland or Serbia

Company

hirify.global operates in the iGaming sector, developing and supporting high-load digital products and payment-related workflows.

What you will do

  • Plan and execute penetration tests across web applications, APIs, mobile applications, internal and external infrastructure, and AWS environments.
  • Conduct red-team and assumed-breach exercises covering privilege escalation, lateral movement, persistence, and data exfiltration.
  • Assess Kubernetes, cloud-native services, microservices, CI/CD pipelines, and Infrastructure as Code implementations.
  • Test payment systems, wallets, KYC/AML processes, bonus mechanisms, affiliate tracking, and other business-critical workflows.
  • Collaborate with Product, Engineering, AppSec, Payments, Fraud, and compliance stakeholders to prioritize findings and support remediation.
  • Develop testing scripts and tools, contribute to threat modeling, review reports, and guide junior and middle security specialists.

Requirements

  • 4+ years of hands-on penetration testing or offensive security experience.
  • Practical experience in at least three areas including web applications and APIs, internal networks, external infrastructure, cloud environments, or mobile applications.
  • OSCP or an equivalent offensive security certification.
  • Strong knowledge of SAST, SCA, DAST, AWS or GCP, MITRE ATT&CK, OWASP ASVS, OWASP WSTG, and PTES.
  • Experience with Python or Bash, IAM models, Kubernetes, CI/CD pipelines, and Infrastructure as Code tools such as GitLab, GitHub Actions, Jenkins, Terraform, Helm, or CloudFormation.
  • Upper-Intermediate English or higher, strong reporting and communication skills, and knowledge of PCI DSS, ISO 27001, NIST, and GDPR.

Nice to have

  • Advanced offensive security certifications such as OSWE, OSEP, OSED, CRTO, BSCP, ARTE, or GRTE.
  • Experience designing secure Kubernetes and AWS architectures.
  • Background in iGaming, fintech, or payment products.
  • Public security research, CVEs, advisories, technical publications, conference presentations, HTB Pro Labs, or strong CTF achievements.
  • Contributions to open-source offensive or defensive security projects.

Culture & Benefits

  • Generous annual leave and paid sick leave.
  • Private medical and dental insurance, sports allowance, and food vouchers.
  • Education budget and professional development opportunities.
  • Modern office with complimentary meals, snacks, and wellness initiatives.
  • Recognition programs, regular team events, and gifts for personal milestones.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →